Back to top anchor
Security Updates

Drupal core - Critical - Cache poisoning - SA-CORE-2023-006

Issue date:

The security update to address SA-CORE-2023-006 will be included in Sector 9.5.8.

Background

In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation. 

Read the Drupal Security Advisory

 

Sector 10 is coming!

Find out more in our Sector 10 roadmap.

Need Help?

Sector is brought to you by Sparks Interactive - supporting Sector from Wellington and Auckland

Open Source award winner!

Sparks Interactive are delighted to accept the Open Source Use in Business award for Sector and the Sector.nz open source platform.

Subscribe for Sector updates